Vulnerability Description
In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Sensitive information such as private keys can appear in these log files allowing for information exposure.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openstack | Octavia | >= 2.0.0, < 2.0.2-5 |
| Redhat | Openstack | 12 |
Related Weaknesses (CWE)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16856Issue TrackingThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16856Issue TrackingThird Party Advisory
FAQ
What is CVE-2018-16856?
CVE-2018-16856 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are reada...
How severe is CVE-2018-16856?
CVE-2018-16856 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-16856?
Check the references section above for vendor advisories and patch information. Affected products include: Openstack Octavia, Redhat Openstack.